How to check whether a platform enforces the rules it publishes
Find the enforcement record behind a platform's safety policy, read it before you spend money there, and know the deadline you can hold the platform to.
on this page · 0 / 0 checked
Someone is about to spend your money on a platform, and the case for it comes with a link to a policy page. The page is thorough. It bans the exact thing you were worried about, in specific language, with examples. You read it, you feel better, you approve the spend. You have just treated a statement of intent as evidence of a control.
Those are different objects. A policy is written once, by people paid to describe what a company wants to prevent. Enforcement happens millions of times a day, by classifiers tuned on last year’s abuse and by reviewers with seconds per decision. The two drift apart quietly, and the usual way anyone finds out is that a researcher goes looking. This guide is about closing that gap with public records instead of faith. It is not for trust-and-safety professionals, who have better instruments than these. It is not legal advice. It is for the operator deciding where to advertise, which vendor to route a client’s data through, and what to do when something ugly turns up next to their name.
The policy check always passes, so it tells you nothing
Pick any large platform and any category of harmful content, and the written ban is already there. Apple’s App Review Guidelines prohibit “overtly sexual or pornographic material”, defined as “explicit descriptions or displays of sexual organs or activities intended to stimulate erotic rather than aesthetic or emotional feelings” [7]. OpenAI’s usage policies, effective 29 October 2025, prohibit “use of someone’s likeness, including their photorealistic image or voice, without their consent in ways that could confuse authenticity” [8]. Meta says it has “longstanding rules against non-consensual intimate imagery” and that it had updated those rules more than a year earlier “to make it even clearer that we don’t allow the promotion of nudify apps or similar services” [5].
Now hold that against what the same company says about enforcement. On 12 June 2025 Meta announced a lawsuit in Hong Kong against Joy Timeline HK Limited, the entity behind the CrushAI apps, and gave the reason plainly: this followed “multiple attempts by Joy Timeline HK Limited to circumvent Meta’s ad review process and continue placing these ads, after they were repeatedly removed for breaking our rules” [5]. Meta also said it had developed “new technology specifically designed to identify these types of ads – even when the ads themselves don’t include nudity” [5]. Read that second sentence slowly. It is an admission about the previous system: it keyed on what the ad showed, so ads that showed nothing got through. The rule banning them was in force the entire time.
This is the shape of the problem in every category, not just this one. The written rule is cheap and public. The detection that would make the rule true is expensive, private, and always one step behind whoever is actively probing it. So a policy page cannot distinguish a platform that enforces well from one that enforces badly, because both have the same page.
Enforcement leaves a public record, and it is searchable
The useful shift is to stop reading policies and start reading enforcement output. Since the EU’s Digital Services Act, there is a large public one.
Article 16 of Regulation (EU) 2022/2065 requires hosting services to put notice mechanisms in place that are “easy to access and user-friendly”, and to notify whoever filed a notice of the decision, “providing information on the possibilities for redress” [2]. Article 17 requires a “clear and specific statement of reasons” for restrictions such as removing content, disabling access to it, or demoting it [2]. Article 24(5) then requires providers of online platforms to submit those decisions and statements of reasons to the Commission, without undue delay, “for the inclusion in a publicly accessible machine-readable database managed by the Commission” [2].
The result is at transparency.dsa.ec.europa.eu, and anyone can use it. Read the front-page figures carefully, because they cover submissions from the last six months rather than all time. On 4 September 2026 that window held 3,795,739,343 statements of reasons, 368 active platforms, and 43% of decisions recorded as fully automated [3]. You can search individual statements, view a dashboard, or take the raw data: daily zipped CSV files, per platform or across all of them, with Parquet available for the global full daily files, in a full version carrying the entire attribute schema or a light version that drops free-text fields longer than 2,000 characters [4].
That gives you something a policy page never will. You can see which platforms file at volume and which barely file at all. You can see which categories a given platform actually actions, and whether its decisions are made by machine or by a person. You can see the shape of a platform’s enforcement change over time, because the files are daily. Article 33 applies the strictest tier of obligations to services with 45 million or more average monthly active recipients in the Union that the Commission has designated as very large [2], so the services most operators care about are inside the regime rather than outside it.
Review at scale is a filter, and filters get mapped
Once you accept that 43% of the recorded moderation decisions in that window were fully automated [3], the failure mode stops being mysterious. Automated review is a classifier. A classifier is a function with a boundary, and anyone with a budget and a few hundred attempts can find where that boundary sits. They do not have to defeat the model. They have to find the cheapest input that lands on the safe side of it.
Meta’s own account describes the mapping in progress. Some advertisers “use benign imagery in their ads to avoid being caught by our nudity detection technology”, while others “quickly create new domain names to replace the websites we block” [5]. The fixes track the evasions one for one: detection that works when the ad contains no nudity, matching technology to find and remove copycat ads more quickly, and an expanded list of “safety-related terms, phrases and emojis” the systems are trained to detect [5]. Meta also says its teams ran investigations that disrupted four separate networks of accounts running these ads in the first months of 2025 [5]. Networks, plural, on a surface with a written ban.
App review has the same property, which is why Apple needs a rule for it. Guideline 2.3.1 states: “Don’t include any hidden, dormant, or undocumented features in your app; your app’s functionality should be clear to end users and App Review” [7]. That rule exists because a review is a snapshot of one build at one moment, and what ships to users afterwards is a different question. Apple also warns that apps used primarily for the “objectification of real people” may be removed without notice [7], which is a rule written in the past tense of things that got approved.
So the practical question about any platform is not whether it has a filter. It is how fast the filter is updated relative to the people mapping it, and the only public signal you have for that is the enforcement record plus how quickly a platform’s own announcements admit to a new class of evasion.
Since May 2026, there is a clock and it is 48 hours
The other thing that changed is that intent is no longer the only lever you have. The TAKE IT DOWN Act was approved on 19 May 2025 as Public Law 119-12 [1]. It requires covered platforms to establish a notice and removal process “not later than 1 year after the date of enactment”, which put the deadline at 19 May 2026 [1]. On receiving a valid removal request through that process, a platform must “as soon as possible, but not later than 48 hours after receiving such request” remove the intimate visual depiction and “make reasonable efforts to identify and remove any known identical copies” [1]. A failure to reasonably comply is treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act, and the FTC enforces it [1].
This matters to you in a narrow but real way. When you or a client is the subject of this material, the message you send a platform is no longer a request for goodwill. It cites a statutory deadline, and the platform’s failure to meet it is an FTC matter rather than a customer service outcome. In the EU, Article 16 of the DSA gives you the parallel: a notice mechanism the platform is obliged to provide, and a decision it is obliged to tell you about [2].
Save the reporting URL for every platform you depend on before you need it. The hour you spend finding the right form is the hour the 48 is counting down.
The ad archives are thinner than people assume
The standard advice is to check the ad library. Do it, but know what you are getting. Meta’s Ad Library API returns archived ads “based on keyword searches of text, images, audio from video, and the call-to-action button”, with a required ad_type parameter whose values are ALL, EMPLOYMENT_ADS, FINANCIAL_PRODUCTS_AND_SERVICES_ADS, HOUSING_ADS and POLITICAL_AND_ISSUE_ADS [6]. Then comes the limit that governs everything else, stated in a note on the country parameter: “Ads that did not reach any location in the EU will only return if they are about social issues, elections or politics” [6]. Access needs a valid OAuth token, the endpoint is read-only, and calls are rate limited [6].
Read together, that means the archive is close to complete for the EU and close to political-only everywhere else. If you are running a US campaign and you want to know what else the platform was serving that week, the archive will not tell you. It is a good tool for checking a specific advertiser or a specific claim, and a poor tool for auditing a surface.
Which pushes the work back to you. Brand safety on an automated ad platform is a monitoring job you own, not a guarantee you bought. Decide in advance how often someone looks at where your ads land, what evidence you keep, and what you do in the first hour if something appears next to your name. That plan costs almost nothing to write and is worthless if you write it during the incident.
If strangers can upload to your site, you are the platform
The last move is to turn the lens around, because the definition is broader than most small operators expect. Under the Act, a covered platform is a website, online service, online application or mobile application that serves the public and either “primarily provides a forum for user-generated content, including messages, videos, images, games, and audio files” or publishes, curates, hosts or makes available nonconsensual intimate visual depictions in the regular course of its trade or business [1]. The exclusions are narrow: broadband access providers, electronic mail, and services consisting primarily of content preselected by the provider where any chat or comment functionality is incidental to that content [1]. There is no small-business carve-out in the definition. A community forum, a public comment section, a client portal where members post images, all sit inside it.
If you ship an iOS app with user content, Apple stacks its own requirements on top. Guideline 1.2 requires “a method for filtering objectionable material from being posted to the app”, “a mechanism to report offensive content and timely responses to concerns”, “the ability to block abusive users from the service”, and “published contact information so users can easily reach you” [7]. Apple also states that removing violating content is the developer’s responsibility, and that if Apple finds such content it will ask you to remove it and to provide a plan to improve compliance [7].
So the honest question is whether you can actually staff a 48-hour clock. Work out the number before you find out the hard way.
requests × minutes ÷ 60. The deadline runs 48 hours from receipt, not 48 business hours, so weekend coverage is part of the number. Computed in the page; nothing is sent anywhere.
What still goes wrong
The public record is EU-shaped. Statements of reasons are filed because the DSA requires them, so the database describes decisions touching the EU and undercounts everything else [2][3]. The categories are coarse and self-reported by the platforms, the front page covers a rolling six months rather than the whole history, and the 43% automation figure is an aggregate across 368 platforms [3], not a claim about any one of them. Filter before you conclude anything, and treat the numbers as a way to compare platforms against each other rather than as an absolute measure of how safe any of them is.
The 48-hour clock is narrower than it sounds. It applies to nonconsensual intimate visual depictions and to covered platforms as the Act defines them [1], not to every kind of content you might want removed, and FTC enforcement is an action against the platform rather than a fast lane for your individual case. Removal is also not the same as erasure. Meta says that since it started sharing this information at the end of March 2025 it has provided more than 3,800 unique URLs to other companies through the Tech Coalition’s Lantern program [5], which tells you the material moves between services faster than any single service can clear it.
And none of this makes a platform trustworthy in advance. The best you get from enforcement data is a lagging indicator: evidence of what a system caught after it had already run. A platform with a strong record can still be sitting on an evasion nobody has published yet, which is the same position Meta was in while its own rules banned exactly the ads it was serving [5]. Read the record, spend accordingly, and keep watching your own placements, because the gap closes only after someone has already been hurt by it.
- 01Public Law 119-12 — TAKE IT DOWN Actgovinfo.gov
- 02Regulation (EU) 2022/2065 — Digital Services Acteur-lex.europa.eu
- 03European Commission — DSA Transparency Databasetransparency.dsa.ec.europa.eu
- 04European Commission — DSA Transparency Database, data downloadtransparency.dsa.ec.europa.eu
- 05Meta Newsroom — Taking action against nudify appsabout.fb.com
- 06Meta for Developers — Ad Library API, ads_archive referencedevelopers.facebook.com
- 07Apple — App Review Guidelinesdeveloper.apple.com
- 08OpenAI — Usage policiesopenai.com